{"id":"CVE-2026-97619","published":"2026-09-25T11:17:16.117","lastModified":"2026-09-25T11:17:16.117","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rw: end write accounting from ->ki_complete\n\nCommit b000145e9907 moved both the fsnotify calls and the write\naccounting out of the kiocb completion handler and into the\nio_req_rw_complete() task_work. However, only the fsnotify part actually\nneeded to move as it may sleep. Ending the write accounting is just a\npercpu_up_read() on the superblock writers sem.\n\nDeferring it is a problem, because it makes dropping SB_FREEZE_WRITE\nprotection depend on the ring owner getting to running task_work. But\nthe task may be blocked in freeze_super(), causing it to never get to\nthat:\n\n  task                             io-wq worker\n  --------------------------------------------------------------\n  io_write()\n    io_kiocb_start_write()         (takes sb_writers, hidden from\n                                    lockdep by __sb_writers_release)\n    write_iter() -> -EIOCBQUEUED\n  ioctl(FS_IOC_SHUTDOWN)\n    bdev_freeze()\n      freeze_super()\n        percpu_down_write()        <- waits for the reader above\n                                   io_write()\n                                     kiocb_start_write()\n                                       percpu_down_read()  <- queued\n                                                              behind the\n                                                              writer\n  <bio completes>\n    io_complete_rw()\n      queues io_req_rw_complete()  <- never runs, task is in D state\n\nEnd the write from io_complete_rw() instead, and leave only the fsnotify\ncalls in task_work.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/055d43a1233edbd80e558889258105ce63051bcd","tags":[]},{"url":"https://git.kernel.org/stable/c/796aa0547557e63338657ed1c487906f9fac4c73","tags":[]},{"url":"https://git.kernel.org/stable/c/cc580cee4dfa2ec9099c30ecbd4d804cbb996432","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}